Security Engineer II
At Flynn Group, we believe in the power of collaboration and value in-person interactions. This setup cultivates casual conversations, problem-solving, and trusted relationships. Our goal is to create an environment where innovation thrives, with office-based teams coming together four days a week to collaborate and thrive, together.
About the role
The Senior Security Engineer is responsible for strengthening Flynn Group’s cyber defense posture across infrastructure, endpoint, cloud, identity, and network environments. This role designs and maintains security hardening standards, supports incident response and security investigations, leads purple-team and tabletop exercises, manages remediation risk tracking, and partners with technology and business teams to assess security risk in new solutions. The ideal candidate is a hands-on security engineer who can operate security tools, translate technical risk into business impact, and drive practical remediation across a distributed enterprise environment.
Responsibilities
- Security Engineering & Hardening
- Develop, maintain, and continuously improve security hardening standards for servers, endpoints, networks, cloud services, and identity platforms.
- Partner with IT and business technology teams to embed secure configuration and least-privilege principles into new and existing solutions.
- Assist with security reviews of key enterprise platforms, tools, and technologies.
- Threat Detection, Response & Security Tooling
- Operate, tune, and improve security platforms such as EDR, antivirus, email security, SIEM, vulnerability management, and related monitoring tools.
- Investigate cybersecurity incidents, document findings, coordinate remediation, and escalate risks based on business impact.
- Develop and improve detection, alerting, response, and remediation playbooks.
- Purple Team, Testing & Resilience
- Lead or coordinate tabletop exercises, attack simulations, penetration testing follow-up, and other purple-team activities.
- Manage honeypot/deception capabilities and use findings to improve detection, response, and control effectiveness.
- Track remediation of security findings from testing, audits, vulnerability scans, and incident reviews.
- Risk, Governance & Business Partnership
- Maintain a security risk roster, document remediation options, and communicate risk clearly to technical and business stakeholders.
- Review new business and technology solutions for security risks, including third-party/vendor risk and AI-related risks.
- Contribute to security policy, standards, audit evidence, and control documentation.
Requirements
- 5+ years of experience in cybersecurity, security engineering, infrastructure security, incident response, vulnerability management, or related disciplines.
- Hands-on experience with security tools such as EDR, SIEM, email security, vulnerability management, endpoint management, or firewall/security platforms.
- Experience identifying, documenting, prioritizing, and driving remediation of security risks.
- Strong written and verbal communication skills, including the ability to explain technical risk to non-technical stakeholders.
Qualifications
- Preferred:
- Experience with Industry Leading EDR solutions, Cloud Security Principles, Industry leading Firewall technology, & Sentinel SIEM.
- Experience with tabletop exercises, penetration testing coordination, red-team/purple-team activities, adversary simulation, or detection engineering.
- Familiarity with NIST CSF, MITRE ATT&CK, ISO 27001, or similar frameworks.
- Experience assessing third-party/vendor security risk and AI-enabled business solutions.
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or equivalent experience.
- Security certifications such as CISSP, Security+, CySA+, GCIH, GCIA, GCFA, CEH, PNPT, or OSCP.
Schedule
In office Monday - Thursday, work from home Friday.
Benefits
- Medical/Dental/Vision
- Retirement and Savings Plan
- Short- and Long-Term Disability
- Basic Life Insurance
- Voluntary Life Insurance
- Tuition Reimbursement
- Paid Time Off
- Flexible/Hybrid Work Schedules
- Company Outings
- Dining Discounts
- On-Site Fitness Center
- On-Site Daycare
- On-Site Café
- FUN Work Environment!